← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Skullcandy Dime 3 Earbuds Vulnerable to Bluetooth Hijacking Due to Unpatchable Firmware

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Skullcandy Dime 3 earbuds (firmware 1.0.0.28) are vulnerable to CVE-2025-20701.
  • The vulnerability allows unauthorized Bluetooth pairing without user consent.
  • Users cannot update affected earbuds to the patched firmware version 1.0.0.30.
  • Attackers can hijack audio, access headset profiles, and capture microphone audio.

Bluetooth Vulnerability Identified in Skullcandy Dime 3

The Carnegie Mellon University CERT Coordination Center (CERT/CC) has issued a warning regarding a high-severity Bluetooth vulnerability, CVE-2025-20701, affecting Skullcandy Dime 3 wireless earbuds. Devices running firmware version 1.0.0.28 are specifically impacted. This flaw, found in the Airoha Bluetooth Audio SDK used by the earbuds, allows nearby unpaired devices to connect without requiring any user interaction or a pairing PIN.

Impact of the Vulnerability

An attacker within close range can exploit this vulnerability to establish a trusted connection with the earbuds. Once paired, the attacker's device can automatically reconnect, enabling them to interrupt the owner's audio playback, hijack audio, access the headset profile, and capture live microphone audio. While a "new device paired" notification may appear, it can be easily missed or dismissed by the user.

Unpatchable Devices for Users

Although Skullcandy states that the security issue was addressed in firmware version 1.0.0.30, CERT/CC notes that regular users have no method to update their devices, either manually or through the Skullcandy application. This means that existing units sold with the vulnerable firmware version 1.0.0.28 cannot be updated by customers to a safe version, leaving them exposed to the exploit.

Broader Industry Impact and Discovery

CVE-2025-20701 is a missing-authentication problem that affects a range of earbud and headphone products from multiple vendors. ERNW researchers discovered the vulnerability and presented it at the TROOPER cybersecurity conference. Airoha published SDK updates to address the issue, and some manufacturers, including Apple for its Beats Studio Buds, have since released firmware updates to incorporate these fixes.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~16 min · 14 stories · Sep 10

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The CERT Coordination Center (CERT/CC) reported that Skullcandy Dime 3 wireless earbuds with firmware version 1.0.0.28 are susceptible to a high-severity Bluetooth hijacking vulnerability (CVE-2025-20701). This flaw allows nearby unpaired devices to connect without user interaction, and affected users cannot update their earbuds to a patched firmware version.